Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-2184

Опубликовано: 10 сент. 2012
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Session fixation vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack web sessions via unspecified vectors.

Комментарий

Per: http://cwe.mitre.org/data/definitions/384.html 'CWE-384: Session Fixation'

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:change_and_configuration_management_database:6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:change_and_configuration_management_database:7.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:maximo_asset_management:7.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:maximo_asset_management:7.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:maximo_service_desk:6.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:smartcloud_control_desk:7.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_asset_management_for_it:6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_asset_management_for_it:6.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_asset_management_for_it:7.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_asset_management_for_it:7.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_asset_management_for_it:7.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_service_request_manager:7.0:*:*:*:*:*:*:*

EPSS

Процентиль: 69%
0.00609
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

Session fixation vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack web sessions via unspecified vectors.

EPSS

Процентиль: 69%
0.00609
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other